WO2009017572A2 - System and method of tamper-resistant control - Google Patents

System and method of tamper-resistant control Download PDF

Info

Publication number
WO2009017572A2
WO2009017572A2 PCT/US2008/008358 US2008008358W WO2009017572A2 WO 2009017572 A2 WO2009017572 A2 WO 2009017572A2 US 2008008358 W US2008008358 W US 2008008358W WO 2009017572 A2 WO2009017572 A2 WO 2009017572A2
Authority
WO
WIPO (PCT)
Prior art keywords
management processor
flag
provisioning
electronic device
firmware
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/US2008/008358
Other languages
French (fr)
Other versions
WO2009017572A3 (en
Inventor
Jeffrey Kevin Jeansonne
Wei Ze Liu
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Hewlett Packard Development Co LP
Original Assignee
Hewlett Packard Development Co LP
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Hewlett Packard Development Co LP filed Critical Hewlett Packard Development Co LP
Priority to BRPI0812667-4A2 priority Critical patent/BRPI0812667B1/en
Priority to KR1020107002168A priority patent/KR101533857B1/en
Priority to DE112008002005T priority patent/DE112008002005T5/en
Priority to CN200880101146.8A priority patent/CN101790724B/en
Priority to GB1001252.4A priority patent/GB2464043B/en
Priority to JP2010519188A priority patent/JP5154646B2/en
Publication of WO2009017572A2 publication Critical patent/WO2009017572A2/en
Publication of WO2009017572A3 publication Critical patent/WO2009017572A3/en
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/57Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
    • G06F21/572Secure firmware programming, e.g. of basic input output system [BIOS]
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/305Authentication, i.e. establishing the identity or authorisation of security principals by remotely controlling device operation
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • G06F21/34User authentication involving the use of external additional devices, e.g. dongles or smart cards
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/57Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
    • G06F21/575Secure boot
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/70Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
    • G06F21/71Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information
    • G06F21/74Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information operating in dual or compartmented mode, i.e. at least one secure mode
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F2221/00Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/21Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/2105Dual mode as a secondary aspect
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F2221/00Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/21Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/2107File encryption
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F2221/00Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/21Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/2147Locking files
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F2221/00Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/21Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/2153Using hardware token as a secondary aspect

Definitions

  • Networked electronic devices are configurable to be controlled from remote locations.
  • management processing chipsets can be utilized to provide remote access from a server to enable, for example, a system administrator to turn on, turn off, boot and/or otherwise operate the electronic device.
  • a system administrator to turn on, turn off, boot and/or otherwise operate the electronic device.
  • the ability of an unauthorized third-party to access and gain control of such electronic devices increase unless numerous difficult and cumbersome set-up steps, operations and/or safeguards are conducted/implemented by the user/administrator of the networked electronic device.
  • FIGURE 1 is a block diagram of an embodiment of a tamper- resistant control system
  • FIGURE 2 is a flow diagram illustrating an embodiment of a tamper-resistant control method.
  • communication network 14 comprises a local area network; however, it should be understood that communications network 14 may be any type of wired and/or wireless communication network (e.g., the Internet, a cellular network, etc.) that enables communications between electronic devices 12i, 12 2 and/or 12 3 .
  • communications network 14 may be any type of wired and/or wireless communication network (e.g., the Internet, a cellular network, etc.) that enables communications between electronic devices 12i, 12 2 and/or 12 3 .
  • electronic device 12i comprises a server 16 and electronic devices 12 2 and 12 3 each comprise workstations 18 and 20, respectively, coupled to server 16 via communication network 14.
  • electronic devices 12 2 and 12 3 comprise a processor 22, firmware 24, a management processor 26 and at least one input/output (I/O) port 28 such as, for example, a universal serial bus (USB) I/O port 30 to receive a USB key 32.
  • firmware 24 is coupled to processor 22, management processor 26 and I/O port 28 and is configured to provide boot-up functionality for electronic devices 12 2 and 12 3 .
  • firmware 24 executes initial power-on instructions such as configuring processor 22 and causing processor 22 to begin executing instructions at a predetermined time.
  • Firmware 24 may comprise a basic input/output system (BIOS) 34; however it should be understood that firmware 24 may comprise other systems or devices for providing boot-up functionality.
  • BIOS 34 comprises a security module 36 to limit access to BIOS 34 (e.g., to users having a password).
  • Security module 36 may comprise hardware, software, or a combination of hardware and software, and is used to verify or authenticate the identity of a user attempting to access BIOS 34.
  • management processor In the embodiment illustrated in FIGURE 1 , management processor
  • management processor 26 is configured to facilitate remote access to electronic devices 12 2 and 12 ⁇ via communications network 14.
  • management processor 26 of each electronic device 12 2 and 12 3 enables a network administrator utilizing electronic device 12i to remotely access and control electronic devices 12 2 and 12 3 via communications network 14.
  • management processor 26 enables a user of electronic device 12i to turn on, turn off, boot, and/or otherwise control electronic devices 12 2 and/or 12 3 remotely from electronic device ⁇ 2 ⁇ .
  • management processor In the embodiment illustrated in FIGURE 1 , management processor
  • enable/disable register 40 comprises firmware 38, an enable/disable register 40 and a management register 42.
  • Registers 40 and 42 comprise information stored by management processor 26 associated with various preset and/or operating parameters of management processor 26 to enable provisioning of management processor 26.
  • the various preset and/or operating parameters of management processor 26 may be configured in the field prior to leaving the manufacturer of management processor 26.
  • enable/disable register 40 comprises an enable/disable flag 44 stored in non-volatile memory thereof.
  • Enable/disable flag 44 is used to indicate a setting for management processor 26 as either being enabled for use or disabled for non-use.
  • enable/disable flag 44 is used to indicate whether management processor 26 is enabled to facilitate communication with electronic device 12-
  • enable/disable flag 44 is set to "YES,” the setting for management processor 26 comprises an enabled setting to enable communication between electronic device 12i and electronic devices 12 2 and 12 3 via management processor 26.
  • enable/disable flag 44 is set to "NO,” the setting for management processor 26 comprises a disabled setting to otherwise disable management processor 26 to prevent use thereof. It should be understood that flag 44 may be otherwise set for indicating the enabled or disabled state of management processor 26.
  • management register 42 comprises an none/AMT flag 46 stored in non-volatile memory thereof. None/AMT flag 46 is used to indicate a setting for management processor 26 as either being configured in an AMT mode or a non- AMT mode.
  • none/AMT flag 46 is used to indicate whether management processor 26 is enabled to facilitate communication with electronic device 12 1 .
  • the setting for management processor 26 comprises an enabled setting to enable communication between electronic device 12i and electronic devices 12 2 and 12 ⁇ via management processor 26.
  • the setting for management processor 26 comprises a disabled setting to otherwise disable management processor 26 to prevent use thereof.
  • flag 46 may be otherwise set for indicating the enabled or disabled state of management processor 26.
  • enable/disable register 40 and a management register 42 are set to "YES" such that management processor 26 is configured for provisioning. In the embodiment illustrated in FIGURE 1 , enable/disable flag 44 none/AMT flag 46 are both set to "YES.”
  • BIOS 34 comprises a provisioning setting 48 to enable provisioning of management processor 26 for communication with electronic device 12-
  • provisioning setting 48 comprises a provisioning enable/disable flag 50 stored in non-volatile memory thereof.
  • Provisioning enable/disable flag 50 is used to indicate a setting for BIOS 34 as either being enabled for provisioning (e.g., establishing access rights and privileges to ensure the security thereof) management processor 26 (e.g., establishing access rights and privileges to ensure the security thereof) or disabled to block and/or otherwise prohibit provisioning of management processor 26.
  • provisioning enable/disable flag 50 is used to indicate whether BIOS 24 is set to facilitate provisioning.
  • provisioning enable/disable flag 50 if provisioning enable/disable flag 50 is set to "YES,” the setting for BIOS 24 comprises a provisioning setting to enable provisioning.
  • provisioning enable/disable flag 50 if provisioning enable/disable flag 50 is set to "NO,” the setting for BIOS 24 comprises a disabled setting to prohibit and/or otherwise block provisioning of management processor 26, thereby preventing unauthorized access to management processor 26 and control of electronic devices 12 2 and 12 3 .
  • security module 36 prevents and/or substantially reduces the likelihood of an unauthorized party accessing BIOS 24 to modify and/or otherwise change provisioning setting 48. Accordingly, management processors 26 of each electronic device 12 2 and 12 ⁇ remain locked (e.g., unable to be provisioned) until provisioning setting 48 in BIOS 24 is set to "YES" to prevent tampering and/or unauthorized provisioning.
  • electronic device 12i comprises a management console 52 to enable and control communications via communication network 14 with electronic devices 12 2 and/or 12 3 , respectively, once management processor(s) 26 has been provisioned for communication with electronic device 12i.
  • management console 52 enables a network administrator utilizing electronic device 12i to remotely access and control electronic device 12 2 and/or 12 3 via communications network 14 through management processor 26.
  • management console 52 and management processor 26 enable the network administrator to turn on, turn off, boot, and/or otherwise control electronic device 12 2 and 12 3 remotely from electronic device 12-
  • electronic device 12i comprises a memory 54 comprising an encryption key index 56 and provisioning data 58.
  • encryption data 56 is configured to store encryption keys consisting of a unique key identifier, a corresponding machine identifier (e.g., an identifier to clearly identify each electronic device 12 communicatively coupled to server 16) and a password for electronic devices 12 2 and 12 3 .
  • encryption data 56 is storable on a storage device such as, for example, a USB key 32 as encryption data 60 for identifying and securing communications when provisioning electronic devices 12 2 and 12 3 .
  • USB key 32 coupleable to I/O port 28 and to enable management processor 26 to transmit encryption data 60 to electronic device 12i for comparison with the data contained in encryption data 56 for authentication of electronic device 12i prior to commencing provisioning of management processor 26. According to some embodiments, USB key 32 is also coupleable to I/O port 28 of electronic device 12 2 for authentication prior to commencing provisioning of management processor 26 of electronic device 12 2 .
  • provisioning setting 48 is set for provisioning (e.g., provisioning enable/disable flag 50 is set to "YES")
  • the method proceeds to decisional blocks 206 and 208 to determine whether management processor 26 is configured in the AMT mode and enabled mode, respectively. If at decisional block 206 or 208, processor 28 is not in the AMT mode or the enabled mode, the method ends. If at decisional blocks 206 and 208, management processor 26 is configured in the AMT mode and the enabled mode, respectively, the method proceeds to block 210 to enable to communicate with input/output port 28 to locate encryption data 60. For example, in FIGURE 2, BIOS 34 searches all USB ports for USB key 32 coupled to electronic device 12.
  • BIOS 34 reads encryption data 60 to obtain the assigned password, key and machine identifier for the particular electronic device 12 2 and/or 12 3 that USB key 32 is coupled thereto.
  • BIOS 34 communicates the password, key and machine identifier to management processor 26 to enable management processor 26 to connect to electronic device 12i via communications network 14.
  • management processor 26 transmits encryption data 60 to electronic device 12i to ensure that encryption data 60 matches encryption data on electronic device 12i (e.g., corresponding to encryption data 56), as indicated at block 218. If at decisional block 220 verification is successful, electronic device 12 1 transmits an encryption certificate to electronic device 12i to facilitate secure transmission of provisioning data 58 to provision management processor 26, as indicated in bocks 222 and 224. If at decisional block 220 verification is unsuccessful, the method ends.
  • provisioning settings 48 in BIOS 24 secure and/or otherwise prevent unauthorized access to and provisioning of management processor 26.

Landscapes

  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Hardware Design (AREA)
  • Software Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Mathematical Physics (AREA)
  • Stored Programmes (AREA)
  • Storage Device Security (AREA)
  • Small-Scale Networks (AREA)

Abstract

A method of tamper-resistant control comprising reading a flag (50) of an electronic device (12) with firmware (24), the flag (50) indicating a provision enable/disable state of the electronic device (12) and provisioning a management processor (26) of the electronic device (12) to facilitate communications between the management processor (26) and a server (16) in response to reading the flag (50) indicating a provision enable/disable state

Description

SYSTEM AND METHOD OF TAMPER-RESISTANT CONTROL
BACKGROUND
[0001] Networked electronic devices are configurable to be controlled from remote locations. For example, in some networked electronic devices, management processing chipsets can be utilized to provide remote access from a server to enable, for example, a system administrator to turn on, turn off, boot and/or otherwise operate the electronic device. However, the ability of an unauthorized third-party to access and gain control of such electronic devices increase unless numerous difficult and cumbersome set-up steps, operations and/or safeguards are conducted/implemented by the user/administrator of the networked electronic device.
BRIEF DESCRIPTION OF THE DRAWINGS
[0002] FIGURE 1 is a block diagram of an embodiment of a tamper- resistant control system; and
[0003] FIGURE 2 is a flow diagram illustrating an embodiment of a tamper-resistant control method.
DETAILED DESCRIPTION OF THE DRAWINGS
[0004] FIGURE 1 is a diagram illustrating an embodiment of a tamper resistant control system 10. In the embodiment illustrated in Figure 1 , system 10 comprises one or more electronic devices 12i, 122 and/or 123 communicatively coupled via a communications network 14. In the embodiment illustrated in FIGURE 1 , three electronic devices 12-ι, 122 and/or 123 are illustrated; however, it should be understood that a greater or fewer number of electronic devices 12i, 122 and/or 123 may be used in connection with system 10. In the embodiment illustrated in FIGURE 1 , electronic devices 12i, 122 and/or 123 may comprise any type of electronic devices such as, but not limited to, desktop computers, portable notebook computers, convertible portable computers, tablet computers, gaming devices, workstations and/or servers. According to some embodiments, communication network 14 comprises a local area network; however, it should be understood that communications network 14 may be any type of wired and/or wireless communication network (e.g., the Internet, a cellular network, etc.) that enables communications between electronic devices 12i, 122 and/or 123.
[0005] In the embodiment illustrated in FIGURE 1 , electronic device 12i comprises a server 16 and electronic devices 122 and 123 each comprise workstations 18 and 20, respectively, coupled to server 16 via communication network 14. In the embodiment illustrated in FIGURE 1 , electronic devices 122 and 123 comprise a processor 22, firmware 24, a management processor 26 and at least one input/output (I/O) port 28 such as, for example, a universal serial bus (USB) I/O port 30 to receive a USB key 32. In FIGURE 1 , firmware 24 is coupled to processor 22, management processor 26 and I/O port 28 and is configured to provide boot-up functionality for electronic devices 122 and 123. For example, in some embodiments, firmware 24 executes initial power-on instructions such as configuring processor 22 and causing processor 22 to begin executing instructions at a predetermined time. Firmware 24 may comprise a basic input/output system (BIOS) 34; however it should be understood that firmware 24 may comprise other systems or devices for providing boot-up functionality. In the embodiment illustrated in FIGURE 1 , BIOS 34 comprises a security module 36 to limit access to BIOS 34 (e.g., to users having a password). Security module 36 may comprise hardware, software, or a combination of hardware and software, and is used to verify or authenticate the identity of a user attempting to access BIOS 34. [0006] In the embodiment illustrated in FIGURE 1 , management processor
26 is configured to facilitate remote access to electronic devices 122 and 12β via communications network 14. For example, in the embodiment illustrated in FIGURE 1 , management processor 26 of each electronic device 122 and 123 enables a network administrator utilizing electronic device 12i to remotely access and control electronic devices 122 and 123 via communications network 14. For example, according to some embodiments, management processor 26 enables a user of electronic device 12i to turn on, turn off, boot, and/or otherwise control electronic devices 122 and/or 123 remotely from electronic device ^2^.
[0007] In the embodiment illustrated in FIGURE 1 , management processor
26 comprises firmware 38, an enable/disable register 40 and a management register 42. Registers 40 and 42 comprise information stored by management processor 26 associated with various preset and/or operating parameters of management processor 26 to enable provisioning of management processor 26. For example, the various preset and/or operating parameters of management processor 26 may be configured in the field prior to leaving the manufacturer of management processor 26. In FIGURE 1 , enable/disable register 40 comprises an enable/disable flag 44 stored in non-volatile memory thereof. Enable/disable flag 44 is used to indicate a setting for management processor 26 as either being enabled for use or disabled for non-use. For example, enable/disable flag 44 is used to indicate whether management processor 26 is enabled to facilitate communication with electronic device 12-|. Thus, in some embodiments, if enable/disable flag 44 is set to "YES," the setting for management processor 26 comprises an enabled setting to enable communication between electronic device 12i and electronic devices 122 and 123 via management processor 26. Correspondingly, if enable/disable flag 44 is set to "NO," the setting for management processor 26 comprises a disabled setting to otherwise disable management processor 26 to prevent use thereof. It should be understood that flag 44 may be otherwise set for indicating the enabled or disabled state of management processor 26. [0008] Similarly, management register 42 comprises an none/AMT flag 46 stored in non-volatile memory thereof. None/AMT flag 46 is used to indicate a setting for management processor 26 as either being configured in an AMT mode or a non- AMT mode. For example, none/AMT flag 46 is used to indicate whether management processor 26 is enabled to facilitate communication with electronic device 121. Thus, in some embodiments, if none/AMT flag 46 is set to "YES," the setting for management processor 26 comprises an enabled setting to enable communication between electronic device 12i and electronic devices 122 and 12β via management processor 26. Correspondingly, if none/AMT flag 46 is set to "NO," the setting for management processor 26 comprises a disabled setting to otherwise disable management processor 26 to prevent use thereof. It should be understood that flag 46 may be otherwise set for indicating the enabled or disabled state of management processor 26. According to some embodiments, enable/disable register 40 and a management register 42 are set to "YES" such that management processor 26 is configured for provisioning. In the embodiment illustrated in FIGURE 1 , enable/disable flag 44 none/AMT flag 46 are both set to "YES."
[0009] In the embodiment illustrated in FIGURE 1 , BIOS 34 comprises a provisioning setting 48 to enable provisioning of management processor 26 for communication with electronic device 12-|. In FIGURE 1 , provisioning setting 48 comprises a provisioning enable/disable flag 50 stored in non-volatile memory thereof. Provisioning enable/disable flag 50 is used to indicate a setting for BIOS 34 as either being enabled for provisioning (e.g., establishing access rights and privileges to ensure the security thereof) management processor 26 (e.g., establishing access rights and privileges to ensure the security thereof) or disabled to block and/or otherwise prohibit provisioning of management processor 26. For example, provisioning enable/disable flag 50 is used to indicate whether BIOS 24 is set to facilitate provisioning. Thus, in some embodiments, if provisioning enable/disable flag 50 is set to "YES," the setting for BIOS 24 comprises a provisioning setting to enable provisioning. Correspondingly, if provisioning enable/disable flag 50 is set to "NO," the setting for BIOS 24 comprises a disabled setting to prohibit and/or otherwise block provisioning of management processor 26, thereby preventing unauthorized access to management processor 26 and control of electronic devices 122 and 123. In the embodiment illustrated in FIGURE 1 , security module 36 prevents and/or substantially reduces the likelihood of an unauthorized party accessing BIOS 24 to modify and/or otherwise change provisioning setting 48. Accordingly, management processors 26 of each electronic device 122 and 12β remain locked (e.g., unable to be provisioned) until provisioning setting 48 in BIOS 24 is set to "YES" to prevent tampering and/or unauthorized provisioning.
[0010] In the embodiment illustrated in FIGURE 1 , electronic device 12i comprises a management console 52 to enable and control communications via communication network 14 with electronic devices 122 and/or 123, respectively, once management processor(s) 26 has been provisioned for communication with electronic device 12i. For example, in the embodiment illustrated in FIGURE 1 , management console 52 enables a network administrator utilizing electronic device 12i to remotely access and control electronic device 122 and/or 123 via communications network 14 through management processor 26. Thus, according to some embodiments, management console 52 and management processor 26 enable the network administrator to turn on, turn off, boot, and/or otherwise control electronic device 122 and 123 remotely from electronic device 12-|.
[0011] In FIGURE 1 , electronic device 12i comprises a memory 54 comprising an encryption key index 56 and provisioning data 58. According to some embodiments, encryption data 56 is configured to store encryption keys consisting of a unique key identifier, a corresponding machine identifier (e.g., an identifier to clearly identify each electronic device 12 communicatively coupled to server 16) and a password for electronic devices 122 and 123. In FIGURE 1 , encryption data 56 is storable on a storage device such as, for example, a USB key 32 as encryption data 60 for identifying and securing communications when provisioning electronic devices 122 and 123. In operation, USB key 32 coupleable to I/O port 28 and to enable management processor 26 to transmit encryption data 60 to electronic device 12i for comparison with the data contained in encryption data 56 for authentication of electronic device 12i prior to commencing provisioning of management processor 26. According to some embodiments, USB key 32 is also coupleable to I/O port 28 of electronic device 122 for authentication prior to commencing provisioning of management processor 26 of electronic device 122.
[0012] FIGURE 2 is a flow diagram illustrating an embodiment of a tamper-resistant control method. In FIGURE 2, the method begins at block 200 wherein BIOS 34 executes a boot routine (e.g., in response to a power-on or wake event). At block 202, BIOS 34 reads provisioning settings 48 in BIOS 34 to check flag 50 to determine whether system 10 is configured for provisioning. If at decisional block 204 provisioning setting 48 is not set for provisioning (e.g., provisioning enable/disable flag 50 is set to "NO"), the method ends and management processor 26 cannot be provisioned. If however, at decisional block 204, provisioning setting 48 is set for provisioning (e.g., provisioning enable/disable flag 50 is set to "YES"), the method proceeds to decisional blocks 206 and 208 to determine whether management processor 26 is configured in the AMT mode and enabled mode, respectively. If at decisional block 206 or 208, processor 28 is not in the AMT mode or the enabled mode, the method ends. If at decisional blocks 206 and 208, management processor 26 is configured in the AMT mode and the enabled mode, respectively, the method proceeds to block 210 to enable to communicate with input/output port 28 to locate encryption data 60. For example, in FIGURE 2, BIOS 34 searches all USB ports for USB key 32 coupled to electronic device 12. At block 210, BIOS 34 reads encryption data 60 to obtain the assigned password, key and machine identifier for the particular electronic device 122 and/or 123 that USB key 32 is coupled thereto. At block 214, BIOS 34 communicates the password, key and machine identifier to management processor 26 to enable management processor 26 to connect to electronic device 12i via communications network 14. At block 216, management processor 26 transmits encryption data 60 to electronic device 12i to ensure that encryption data 60 matches encryption data on electronic device 12i (e.g., corresponding to encryption data 56), as indicated at block 218. If at decisional block 220 verification is successful, electronic device 121 transmits an encryption certificate to electronic device 12i to facilitate secure transmission of provisioning data 58 to provision management processor 26, as indicated in bocks 222 and 224. If at decisional block 220 verification is unsuccessful, the method ends.
[0013] Thus, embodiments of system 10 enable management processor
26 to be configured in an enabled mode prior to using and/or otherwise booting an electronic device 12. According to some embodiments, provisioning settings 48 in BIOS 24 secure and/or otherwise prevent unauthorized access to and provisioning of management processor 26.

Claims

WHAT IS CLAIMED IS:
1. A method of tamper-resistant control, comprising: reading at least one flag (50) of an electronic device (12) with firmware (24), the flag (50) indicating a provisioning enable/disable state of the electronic device (12); and provisioning a management processor (26) of the electronic device (12) to facilitate communications between the management processor (26) and a server (16) in response to reading the flag (50) indicating a provisioning enable/disable state.
2. The method of Claim 1 , wherein reading the flag (50) by the firmware (24) comprises reading the flag (50) with a basic input/output system (BIOS) (34).
3. The method of Claim 1 , further comprising reading a universal serial bus (USB) port (30) to locate encryption data (60) stored in a USB key (32).
4. The method of Claim 1 , further comprising provisioning the management processor (26) in response to determining the state of a none/AMT flag (46) in the management processor (26).
5. The method of Claim 1 , further comprising provisioning the management processor (26) in response to determining the state of an enable/disabled flag (44) in the management processor (26).
6. The method of Claim 1 , further comprising setting a block in firmware (24) to prevent access to management processor (26) firmware (38).
7. A tamper-resistant configuration system (10), comprising: an electronic device (12) having a firmware (24) setting (48) comprising at least one flag (50), the flag (50) indicating a provisioning enable/disable state of a management processor (26) of the electronic device (12); and the firmware (24) configured to send a provisioning data record to the management processor (26) in response to reading a provisioning state.
8. The system (10) of Claim 7, wherein the firmware (24) comprises a basic input/output system (BIOS) (34).
9. The system (10) of Claim 7, wherein the management processor (26) comprises a firmware (38) setting (42) comprising a flag (46) indicating a non/AMT state.
10. The system (10) of Claim 7, wherein the management processor (26) comprises a firmware (38) setting (40) comprising a flag (44) indicating an enabled/disabled mode.
PCT/US2008/008358 2007-07-31 2008-07-07 System and method of tamper-resistant control Ceased WO2009017572A2 (en)

Priority Applications (6)

Application Number Priority Date Filing Date Title
BRPI0812667-4A2 BRPI0812667B1 (en) 2007-07-31 2008-07-07 tamper resistant control method and tamper resistant configuration system
KR1020107002168A KR101533857B1 (en) 2007-07-31 2008-07-07 System and method of tamper-resistant control
DE112008002005T DE112008002005T5 (en) 2007-07-31 2008-07-07 System and method of tamper-resistant control
CN200880101146.8A CN101790724B (en) 2007-07-31 2008-07-07 The system and method for anti-tamper control
GB1001252.4A GB2464043B (en) 2007-07-31 2008-07-07 System and method of tamper-resistant control
JP2010519188A JP5154646B2 (en) 2007-07-31 2008-07-07 System and method for unauthorized use prevention control

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
US11/888,428 US8185941B2 (en) 2007-07-31 2007-07-31 System and method of tamper-resistant control
US11/888,428 2007-07-31

Publications (2)

Publication Number Publication Date
WO2009017572A2 true WO2009017572A2 (en) 2009-02-05
WO2009017572A3 WO2009017572A3 (en) 2009-03-26

Family

ID=40305097

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/US2008/008358 Ceased WO2009017572A2 (en) 2007-07-31 2008-07-07 System and method of tamper-resistant control

Country Status (8)

Country Link
US (1) US8185941B2 (en)
JP (1) JP5154646B2 (en)
KR (1) KR101533857B1 (en)
CN (1) CN101790724B (en)
BR (1) BRPI0812667B1 (en)
DE (1) DE112008002005T5 (en)
GB (1) GB2464043B (en)
WO (1) WO2009017572A2 (en)

Families Citing this family (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP5369502B2 (en) * 2008-06-04 2013-12-18 株式会社リコー Device, management device, device management system, and program
KR101440707B1 (en) * 2010-02-12 2014-09-17 미쓰비시덴키 가부시키가이샤 Programmable controller
EP3073405B1 (en) * 2015-03-23 2019-02-06 ABB Schweiz AG Method and device providing secure vendor service access
US11698972B2 (en) * 2021-07-22 2023-07-11 Dell Products L.P. Method to securely transfer root of trust responsibilities on a common shared motherboard

Family Cites Families (18)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US2200700A (en) * 1939-07-13 1940-05-14 Kenneth F Mills Spindle bracket
KR19990060725A (en) 1997-12-31 1999-07-26 전주범 Camera Adjuster of Video Communication System
US6415324B1 (en) * 1999-02-19 2002-07-02 International Business Machines Corporation Data processing system and method for permitting a client computer system to temporarily prohibit remote management
US6647434B1 (en) * 1999-12-28 2003-11-11 Dell Usa, L.P. Multifunction device with register space for individually enabling or disabling a function of plurality of functions in response to function configuration
KR20020039046A (en) 2000-11-20 2002-05-25 윤종용 Method of remotely controlling wireless terminator
JP2002312326A (en) * 2001-04-17 2002-10-25 Smart Card Technologies:Kk Multiple authentication method using an electronic device having a USB interface
WO2002086747A1 (en) * 2001-04-24 2002-10-31 Broadcom Corporation Integrated gigabit ethernet pci-x controller
US7313819B2 (en) * 2001-07-20 2007-12-25 Intel Corporation Automated establishment of addressability of a network device for a target network environment
US20030051013A1 (en) 2001-09-12 2003-03-13 International Business Machines Corporation Method for providing a provisioning key for connecting an electronic device to a computer network
US20030097587A1 (en) * 2001-11-01 2003-05-22 Gulick Dale E. Hardware interlock mechanism using a watchdog timer
US7155305B2 (en) 2003-11-04 2006-12-26 Universal Electronics Inc. System and methods for home appliance identification and control in a networked environment
US20060089819A1 (en) * 2004-10-25 2006-04-27 Dubal Scott P Chipset activation
US20070011491A1 (en) 2005-06-30 2007-01-11 Priya Govindarajan Method for platform independent management of devices using option ROMs
US8745224B2 (en) 2005-12-28 2014-06-03 Intel Corporation Method and apparatus for dynamic provisioning of an access control policy in a controller hub
US8099495B2 (en) 2005-12-29 2012-01-17 Intel Corporation Method, apparatus and system for platform identity binding in a network node
US7930728B2 (en) * 2006-01-06 2011-04-19 Intel Corporation Mechanism to support rights management in a pre-operating system environment
US9081946B2 (en) * 2006-03-29 2015-07-14 Stmicroelectronics, Inc. Secure mass storage device
US8984265B2 (en) * 2007-03-30 2015-03-17 Intel Corporation Server active management technology (AMT) assisted secure boot

Also Published As

Publication number Publication date
KR20100053537A (en) 2010-05-20
WO2009017572A3 (en) 2009-03-26
JP2010535380A (en) 2010-11-18
GB2464043B (en) 2012-09-05
DE112008002005T5 (en) 2010-06-10
KR101533857B1 (en) 2015-07-03
BRPI0812667A2 (en) 2014-12-23
US20090037749A1 (en) 2009-02-05
GB201001252D0 (en) 2010-03-10
BRPI0812667B1 (en) 2019-12-03
JP5154646B2 (en) 2013-02-27
GB2464043A (en) 2010-04-07
CN101790724A (en) 2010-07-28
US8185941B2 (en) 2012-05-22
CN101790724B (en) 2016-03-23

Similar Documents

Publication Publication Date Title
US8909940B2 (en) Extensible pre-boot authentication
US8201239B2 (en) Extensible pre-boot authentication
KR101052128B1 (en) Authentication method, device and system of external storage device
CN102449631B (en) For performing the system and method for bookkeeping
JP5373062B2 (en) System and method for providing system management commands
US7917741B2 (en) Enhancing security of a system via access by an embedded controller to a secure storage device
US9530027B2 (en) Device lock for transit
US20120198538A1 (en) Multi-enclave token
US20100083002A1 (en) Method and System for Secure Booting Unified Extensible Firmware Interface Executables
JP2001290776A (en) Data processing system and data processing method for restoring basic password remotely
EP3704622B1 (en) Remote locking a multi-user device to a set of users
US8181006B2 (en) Method and device for securely configuring a terminal by means of a startup external data storage device
KR100991191B1 (en) Computer security module and computer device applying the same
US8185941B2 (en) System and method of tamper-resistant control
CN100416517C (en) Method for managing data access between storage device and host device
JP4561213B2 (en) Hard disk security management system and method thereof
US12407666B2 (en) Recovery request
US11443075B2 (en) Secure storage system
KR100469647B1 (en) Method for authenticating the right to use a computer and protecting data of a computer based on network
JP2014078185A (en) Information processing system and method and information processing terminal
KR20130119838A (en) Digital system having rights identification information, application system, and service system

Legal Events

Date Code Title Description
WWE Wipo information: entry into national phase

Ref document number: 200880101146.8

Country of ref document: CN

121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 08780013

Country of ref document: EP

Kind code of ref document: A2

WWE Wipo information: entry into national phase

Ref document number: 336/CHENP/2010

Country of ref document: IN

ENP Entry into the national phase

Ref document number: 1001252

Country of ref document: GB

Kind code of ref document: A

Free format text: PCT FILING DATE = 20080707

WWE Wipo information: entry into national phase

Ref document number: 1001252.4

Country of ref document: GB

WWE Wipo information: entry into national phase

Ref document number: 2010519188

Country of ref document: JP

ENP Entry into the national phase

Ref document number: 20107002168

Country of ref document: KR

Kind code of ref document: A

RET De translation (de og part 6b)

Ref document number: 112008002005

Country of ref document: DE

Date of ref document: 20100610

Kind code of ref document: P

122 Ep: pct application non-entry in european phase

Ref document number: 08780013

Country of ref document: EP

Kind code of ref document: A2

REG Reference to national code

Ref country code: DE

Ref legal event code: 8607

ENP Entry into the national phase

Ref document number: PI0812667

Country of ref document: BR

Kind code of ref document: A2

Effective date: 20100107